# Mysql 8 certificates

**URL:** <https://forums.percona.com/t/mysql-8-certificates/19772>\
**Category:** MySQL & MariaDB\
**Created:** [January 25, 2023, 4:53pm UTC](https://forums.percona.com/t/mysql-8-certificates/19772 "2023-01-25T16:53:41Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![rahuls50](https://avatars.discourse-cdn.com/v4/letter/r/db5fbb/32.png) [@rahuls50](https://forums.percona.com/u/rahuls50)\
**Post date:** [January 25, 2023, 4:53pm UTC](https://forums.percona.com/t/mysql-8-certificates/19772/1 "2023-01-25T16:53:41Z")

</div>

hello Mattheb.

Thank you for your response.

Can you please let me know abt the certificate

CA.pem = this is root CA certificate  
server-key.pem = I am confused with this. What it should be  
server-cert.pem= I am confused with this. What it should be

I have wildcard certificate. (eg:- \*.example.com)

Can i use this wildcard certificate as my server-cert.pem.

I have example.crt which includes (root CA, intermidiate ca, \*.example.com)

And also

I have example.pem which includes (root CA, intermidiate ca, \*.example.com , server key)

And does it needs to be in .pem format only.

Please let me know…I always confused when it comes to certificate

---

<div class="post-metadata">

**Author:** ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)\
**Post date:** [January 25, 2023, 9:10pm UTC](https://forums.percona.com/t/mysql-8-certificates/19772/2 "2023-01-25T21:10:20Z")

</div>

I don’t know if MySQL supports wildcard certificates. server-key.pem is the private key of your certificate and sever-cert.pem is the certificate itself.

---

<div class="post-metadata">

**Author:** ![rahuls50](https://avatars.discourse-cdn.com/v4/letter/r/db5fbb/32.png) [@rahuls50](https://forums.percona.com/u/rahuls50)\
**Post date:** [January 27, 2023, 2:15pm UTC](https://forums.percona.com/t/mysql-8-certificates/19772/3 "2023-01-27T14:15:34Z")

</div>

Hello Matthewb

Temporally I am using default certificates that are created on node one and placing same on other 2 nodes. Just want to know do i have to put below details in my my.cnf file.

[mysqld]  
wsrep\_provider\_options=”socket.ssl\_key=server-key.pem;socket.ssl\_cert=server-cert.pem;socket.ssl\_ca=ca.pem”

[sst]  
encrypt=4  
ssl-key=server-key.pem  
ssl-ca=ca.pem  
ssl-cert=server-cert.pem

---

<div class="post-metadata">

**Author:** ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)\
**Post date:** [January 27, 2023, 5:00pm UTC](https://forums.percona.com/t/mysql-8-certificates/19772/4 "2023-01-27T17:00:28Z")

</div>

use this setting and it will apply the SSL parameters to wsrep and SST automatically

```
[mysqld]
pxc-encrypt-cluster-traffic=ON

```

---

<div class="post-metadata">

**Author:** ![rahuls50](https://avatars.discourse-cdn.com/v4/letter/r/db5fbb/32.png) [@rahuls50](https://forums.percona.com/u/rahuls50)\
**Post date:** [January 28, 2023, 6:31am UTC](https://forums.percona.com/t/mysql-8-certificates/19772/5 "2023-01-28T06:31:06Z")

</div>

Hello Matthewb

as encryption is enabled by default. I have created a cluster. How should I verify that my encryption is working or not.

---

<div class="post-metadata">

**Author:** ![Pep\_Pla](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/pep_pla/32/9735_2.png) [@Pep\_Pla](https://forums.percona.com/u/Pep_Pla)\
**Post date:** [January 29, 2023, 10:32am UTC](https://forums.percona.com/t/mysql-8-certificates/19772/6 "2023-01-29T10:32:10Z")

</div>

Hi @rahuls50

You can use `tcpdump` to dump the contents of the tcp packets. For example:

```auto
tcpdump -n --interface lo0 -A tcp dst port 3306

```

Then test unencrypted connection:

```auto
 mysql -h <host> -u<user> -p<password> -P 3306 --ssl-mode=disabled -e "select 'unencrypted_content'

```

You should get a content similar to this:

```auto
10:56:30.519594 IP X.X.X.X.50694 > X.X.X.X.3306: Flags [P.], seq 34:69, ack 84, win 6326, options [nop,nop,TS val 909369158 ecr 1037336205], length 35
E..W..@.@......$...$.......I2.7............
63.F=.~........select 'unencrypted content'

```

To test encrypted connection:

```auto
 mysql -h <host> -u<user> -p<password> -P 3306 -e "select 'encrypted_content'

```

You should get a content similar to this:

```auto
11:30:34.837881 IP X.X.X.X.51334 > X.X.X.X.3306: Flags [P.], seq 36:335, ack 79, win 6378, options [nop,nop,TS val 388257037 ecr 2675164603], length 299
E.._..@.@......$...$....h..t69.............
.$U..s......&...".....E."aC.3#...O.~..D........a... .8h.........	:'QN..c....<.!k4.X..H.......+.,./.#.'.0.$.(.....g.@...k.j.....	...
.2.3.8.9.5...A.....<.=./...............
...
...........#.............0.............	.
.................................+........-.....3.&.$... ....j..#...(L.>..&...cCR.l......

```

As you can see, the encrypted connection is not human readable.

Cheers!
